Security News > 2021 > July > Microsoft Defender for Identity now detects PrintNightmare attacks

Microsoft Defender for Identity now detects PrintNightmare attacks
2021-07-16 12:56

Microsoft has added support for PrintNightmare exploitation detection to Microsoft Defender for Identity to help Security Operations teams detect attackers' attempts to abuse this critical vulnerability.

As revealed by Microsoft program manager Daniel Naim, Defender for Identity now identifies Windows Print Spooler service exploitation and helps block lateral movement attempts within an org's network.

Microsoft Defender for Identity is a cloud-based security solution that leverages on-premises Active Directory signals.

Defender for Identity is bundled with Microsoft 365 E5 but, if you don't have a subscription already, you can get a Security E5 trial right now to give this new feature a spin.

Last week, Microsoft clarified the PrintNightmare patch guidance and shared the steps needed to correctly patch the critical vulnerability after several security researchers tagged the patches issued to address the bug were incomplete.

Until a CVE-2021-34481 patch is available, Microsoft advises admins to disable the Print Spooler service on Windows devices exposed to attacks.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-defender-for-identity-now-detects-printnightmare-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-07-16 CVE-2021-34481 Improper Privilege Management vulnerability in Microsoft products
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.
0.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 381 51 1409 2911 175 4546